German police just dismantled Kratos, a phishing-as-a-service kit that investigators call one of the most widely used criminal toolkits on the planet. That’s the good news. The bad news is what Kratos was built to do: steal live Microsoft 365 session tokens and walk straight past multi-factor authentication without ever needing a password. Every company that got hit by it is still dealing with the fallout, takedown or not. Meanwhile, a separate wave of attackers is proving you don’t even need a phishing kit. Office printers, exposed RDP, and a copy of BitLocker will do the job just fine. This is the state of cybersecurity heading into the back half of 2026: the tools keep changing, but the entry points keep being things nobody bothered to lock down.

Kratos Didn’t Break MFA. It Made MFA Irrelevant.
Here’s the part that should bother every IT team that spent the last two years rolling out MFA as the fix-all: Kratos never tried to guess or steal a password. It used an adversary-in-the-middle proxy that sat between the victim and the real Microsoft login page, relaying every keystroke and, critically, capturing the session cookie issued after the user completed MFA. Once the attacker has that cookie, they’re logged in as the user, no second factor required, no alert triggered.
That’s why a criminal kit built by one developer, according to Indonesian authorities who arrested him, could apparently be sold and reused widely enough to draw a joint German-US law enforcement takedown. Session-token theft scales because it’s cheap to run and devastatingly effective against the exact control most organizations lean on hardest.
The lesson isn’t “MFA is broken.” It’s that MFA without session hardening is a speed bump, not a wall. If your threat detection stack isn’t watching for session tokens replaying from a new IP, a new device fingerprint, or an impossible-travel geolocation, you won’t catch this until the attacker is already forwarding mail rules and pivoting into your tenant.
A Locked Printer Queue Turned Into a Six-Figure Ransom
While Kratos targeted cloud identity, a different set of intrusions documented by Kaspersky’s Securelist team shows attackers going after infrastructure nobody thinks to patch: office printers. The pattern is almost boring in its simplicity. Attackers get in through exposed RDP or MSSQL, deploy legitimate RMM tools to blend in with normal admin traffic, drop a web shell for persistence, and then use BitLocker, Windows’ own disk encryption, against the victim. No custom ransomware binary required. No exotic malware. Just a built-in Windows feature turned into an extortion tool, sometimes finished off by printing the ransom note directly to every printer on the network.
The report describes attackers requesting comparatively small ransoms per victim, betting on volume across many under-defended small and mid-size targets rather than one large payout.
That’s a meaningful shift in incident response math. A single large ransomware operator hitting a hospital chain gets headlines. A criminal group running the same BitLocker-and-printer playbook against hundreds of small businesses for modest sums gets almost none, and collects just as much money with far less risk of drawing an FBI task force.
It also explains why the Anubis ransomware group’s claim against Coca-Cola’s Fairlife subsidiary, roughly a terabyte of allegedly stolen data now being used as leverage, isn’t an outlier. It’s the same incentive structure at a bigger scale: get in through whatever’s exposed, sit quietly, then extort on the way out whether or not you ever deploy a traditional encryptor.
Basic Hardening Still Beats Most of What’s Hitting You
None of this requires exotic defenses. It requires actually doing the boring things consistently, which is where most environments fall down.
- Move to phishing-resistant MFA, FIDO2 security keys or platform passkeys, for anything with access to email, finance, or admin consoles. Adversary-in-the-middle kits like Kratos can’t proxy a hardware-bound key the way they proxy a one-time code.
- Enable continuous access evaluation or equivalent session-risk policies so a stolen cookie gets killed the moment the sign-in pattern looks wrong, not at the next token expiry.
- Get RDP and database ports off the public internet entirely. Put them behind a VPN or zero-trust broker, and pair that with brute-force lockout and rate-limiting at the firewall so credential stuffing doesn’t even get a foothold.
- Treat RMM tools as privileged software. Inventory every remote-management agent that’s allowed to run, and alert on any RMM binary that isn’t on that list, since attackers increasingly install their own copies to look like routine IT work.
- Escrow BitLocker recovery keys somewhere the domain admin account you just lost doesn’t control, ideally in a separate identity tier or offline vault, so an attacker who owns your AD can’t also lock you out of your own disks.
- Segment printers and other embedded devices onto their own VLAN with no route to servers or workstations. They don’t need to talk to your file shares, and they definitely don’t need to print ransom notes.
Security hardening isn’t glamorous, and none of this will get you a keynote slot. But defense in depth is exactly what turns a stolen session cookie into a dead end instead of a domain compromise, and what turns a compromised printer into an isolated nuisance instead of an entry point to your entire environment.
Sources
- Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
- A new extortion cocktail: office printers, small ransoms, and BitLocker
- Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
